Advisories warn of Johnson Controls EasyIO and Illustra flaws
CISA and Canada's Cyber Centre warn of EasyIO credential and data flaws, unpatched FG hard-coded credentials, and an Illustra Standard issue, with no known exploitation.
CISA republished Johnson Controls advisories JCI-PSA-2026-30 and JCI-PSA-2026-20 for EasyIO Neo Series EC and CW building-automation controllers used for HVAC, lighting, and energy. CVE-2026-64893 (CWE-319) is cleartext transmission of credentials and session data that a network attacker could intercept, scored CVSS v3.1 5.4 with high attack complexity, while CVE-2026-64892 (CWE-200) is information exposure that could aid further attacks, scored 3.5 and requiring high privileges plus user interaction; both affect EC V3.3b62 and V3.3b63 and CW V3.3b24 and V3.3b25, and CISA reports no known public exploitation. On October 2, 2026, Canada's Cyber Centre issued AV26-991 covering EasyIO FG before 2.0b52, EasyIO Neo before 3.3b63 and 3.3b25, and EasyIO FS32 before 3.0b63 and 3.3b63, without CVE identifiers or observed exploitation, and urged administrators to apply updates. On October 6, CISA said EasyIO FG firmware 2.0b52 and earlier has CVE-2026-27872 and CVE-2026-27873, hard-coded credentials and improper privilege management scored CVSS 7.7 that require local access and high complexity and could give full device access; the series is end-of-life, unsold since before 2019, will not be patched, and operators should migrate to EasyIO Neo and isolate devices on segmented networks, with no exploitation reported. On October 7, 2026, Canada's Cyber Centre published AV26-1010 for Johnson Controls Illustra Standard - L4L China versions before 6.0.0.66394, citing vendor information as of October 6 and listing no CVE, severity, or exploitation evidence while urging updates. Sources disagree on EasyIO scope: Canada describes broader FG, Neo, and FS32 families as affected before listed builds and cites no CVEs, while CISA names specific Neo EC and CW builds for the two information flaws and includes FG 2.0b52 and earlier—not only versions before that build—for the hard-coded credential issues.
- CVE-2026-64893 (CWE-319) is cleartext transmission of credentials and session data in EasyIO Neo EC V3.3b62 and V3.3b63 and CW V3.3b24 and V3.3b25, CVSS v3.1 5.4 with high attack complexity; CISA reports no known public exploitation…
- CVE-2026-64892 (CWE-200) is information exposure on the same Neo EC and CW builds, CVSS v3.1 3.5, requiring high privileges and user interaction; CISA reports no known public exploitation (JCI-PSA-2026-20).
- EasyIO Neo controllers automate HVAC, lighting, and energy in commercial buildings.
- Canada's AV26-991 (October 2, 2026) lists EasyIO FG before 2.0b52, Neo before 3.3b63 and 3.3b25, and FS32 before 3.0b63 and 3.3b63, with no CVEs or observed exploitation, and urges updates.
Coverage timelineoldest first · each row is one article
- · 7d agoJohnson Controls EasyIO Neo Series EC and CW Controllers
CISA Advisories· 26
CISA discloses low-severity information exposure CVE-2026-64892 in Johnson Controls EasyIO Neo EC and CW controllers.
- · 7d agoJohnson Controls EasyIO Neo Series EC and CW Controllers
CISA Advisories· 36
CISA says Johnson Controls EasyIO Neo controllers transmit credentials in cleartext via CVE-2026-64893, with no known exploitation.
Vulnerabilities in this storyAll →
- CVE-2026-648926.3—Sensitive data exposure in Johnson Controls Easy IO Neopublished · Johnson Controls Easy IO Neo (EC and CW series)+1 related
- CVE-2026-648937.3—Cleartext Sensitive Data Transmission in EasyIO NEOpublished · Johnson Controls EasyIO NEO (Neo Series EC and CW controllers)+1 related